Vulnerabilities
Vulnerable Software
Claris International has resolved an issue of potentially allowing unauthorized access to records stored in databases hosted on FileMaker Server. This issue has been fixed in FileMaker Server 20.3.2 by validating transactions before replying to client requests.
CVSS Score
7.5
EPSS Score
0.003
Published
2024-05-14
Claris FileMaker Server before version 20.3.2 was susceptible to a reflected Cross-Site Scripting vulnerability due to an improperly handled parameter in the FileMaker WebDirect login endpoint. The vulnerability was resolved in FileMaker Server 20.3.2 by escaping the HTML contents of the login error message on the login page.
CVSS Score
6.1
EPSS Score
0.007
Published
2024-04-15


Contact Us

Shodan ® - All rights reserved